Malicious PDF — malware analysis report

Static analysis result for SHA-256 f311bbe3ed0c1ae2…

MALICIOUS

PDF

78.0 KB Created: 2020-07-31 13:19:24 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b2b3c5c5949446f575e4a4c1fad68a50 SHA-1: d67de729e293db176a00ba658dc266bb9388f7f6 SHA-256: f311bbe3ed0c1ae2e725386848ebb398b1e5478f8b337888c223cc62f12cbcb3
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious Link

The PDF contains numerous embedded links, with a critical heuristic firing for PDF_MALICIOUS_REDIRECTOR_LINK indicating redirection to malicious infrastructure via ttraff.cc. Another critical heuristic, PDF_SEO_LINK_FARM, highlights the presence of a large number of external links, many hosted on Shopify, suggesting an attempt to manipulate search engine results or distribute malicious content. The ML classifier also strongly flagged this PDF as malicious.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 3

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.cc/pify?keyword=logical+fallacies+list+pdf
    • http://files.columbiapresbyterianchurch.com/uploads/1/3/0/7/130776206/togixutuwo-jebudepog.pdf
    • http://files.capstoneonline.com/uploads/1/3/0/8/130814596/cdb1abea4c8dc6.pdf
    • http://files.crossfirerec.com/uploads/1/3/1/3/131398406/tipumuju.pdf
    • https://cdn.shopify.com/s/files/1/0428/9842/3967/files/wugejijixabavoxobak.pdf
    • https://cdn.shopify.com/s/files/1/0432/8102/3132/files/3475908914.pdf
    • https://cdn.shopify.com/s/files/1/0427/9464/7719/files/3079937197.pdf
    • https://cdn.shopify.com/s/files/1/0440/8688/6552/files/lufofuxito.pdf
    • https://cdn.shopify.com/s/files/1/0436/8482/3205/files/72880608662.pdf
    • https://cdn.shopify.com/s/files/1/0429/3348/5727/files/50116834561.pdf
    • https://cdn.shopify.com/s/files/1/0430/3588/5721/files/roweka.pdf
    • https://cdn.shopify.com/s/files/1/0433/0687/7080/files/46905239833.pdf
    • https://cdn.shopify.com/s/files/1/0431/0325/6737/files/51580750429.pdf
    • https://cdn.shopify.com/s/files/1/0431/6377/9240/files/86423151771.pdf
    • https://cdn.shopify.com/s/files/1/0431/2878/3002/files/kebiniririnimomoka.pdf
    • https://cdn.shopify.com/s/files/1/0436/5520/0918/files/nupuzoxalinivozexoxifu.pdf
    • https://cdn.shopify.com/s/files/1/0437/1388/8424/files/60964868872.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/

Extracted artifacts 3

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000e1d6.bin
0c7915a9c4be11b5cbb7fca413ca0dfef971ba58cf87841a4d48b45f3040ac25
pdf-font-stream PDF embedded font (sfnt) at offset 0xE1D6 4848 bytes
font_01_sfnt_off0000f265.bin
276a6864a501bad14a2b14173282e77cf08400c86dee44416dab77857d8be3e9
pdf-font-stream PDF embedded font (sfnt) at offset 0xF265 10188 bytes
font_02_sfnt_off0001157a.bin
a0852c4690a6c7c4be107c8faaea32186891696821b3a96aec1037a99786b2f1
pdf-font-stream PDF embedded font (sfnt) at offset 0x1157A 16076 bytes